Safety

Researchers used Anthropic's Claude Mythos to develop a macOS privilege-escalation exploit

Cybersecurity researchers at Calif say they used Anthropic’s Claude Mythos to identify a vulnerability in macOS and to help develop a privilege-escalation method that could lead to full device takeover.

Researchers used Anthropic's Claude Mythos to develop a macOS privilege-escalation exploit

Apple’s operating systems have a long-standing reputation for strong security on both mobile and desktop platforms. Researchers at the cybersecurity firm Calif, however, say they have found a vulnerability in macOS and developed a privilege-escalation method that can expose parts of the system normally kept locked down.

According to The Wall Street Journal, the researchers relied on Anthropic’s Claude Mythos AI tool to identify the vulnerability and to assist in developing a related attack technique. The report states that Mythos located bugs rapidly, although human researchers were still required to complete the exploit development.

The Wall Street Journal also notes that Anthropic considers Mythos sufficiently risky that it is not broadly released by the developer.

Why this matters

The case highlights a key risk posed by advanced AI tools: they can accelerate discovery of software flaws and, potentially, the creation of methods to exploit them. If an AI helps both to find vulnerabilities and to outline steps for exploitation, it could enable faster and more widespread attacks when used by malicious actors.

Apple’s response and next steps

Apple said user security remains “their top priority.” Calif’s researchers have already met with Apple representatives at the company’s headquarters to discuss the security issue. Neither the researchers nor Apple has published technical details; both parties say they will disclose specifics only after Apple issues a patch to fix the vulnerability.

The incident illustrates the dual-use nature of AI tools: they can be leveraged to improve defenses but also create new threats if powerful capabilities are accessed by adversaries.